Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

XG 18.0 and Skype for Business Online/Teams

All:

We continue to experience multiple problems with our Yealink T58A Skype for Business/Teams phones. Some of our symptoms include the following:

  • 3-8 second delay after answering before both sides can hear each other.
  • Caller hears 2-7 rings before the phone itself rings.
  • 3-8 second delay during transfer of incoming caller to another phone in the same subnet
  • Occasional call quality issues

Here's some of the diagnostic information that we're investigating regarding some of our issues:

  • Our XG continues to show that our phones are trying to connect to our primary WAN IP address (and getting blocked by the firewall under the Log comp rule "Appliance Access") on ports 50000-50019. We are aware that these are some of the ports that Skype and now Teams want to connect on for audio, video, and screen sharing, and have set all this up, but the issue appears to be NAT related.
  • We are also getting frequent blocks of 3478 (STUN) requests from Skype for Business servers to our appliance.

Here's a little about us:

  • Phones are still running Skype for Business firmware, and a few user accounts have been moved to Teams Only mode which means they're receiving and making calls from Micorosoft's 3PIP.
  • Almost all of our hardware phones are on the same dedicated subnet.
  • All of our desktop PCs VLAN off of the phones via the dedicated PC Port.
  • We utilize Office 365, so our "Skype" and "Teams" servers are the O365 online versions of everything. We have no SBA or otherwise, we're fully online.
  • We have dual, redundant Internet connections
  • We have a dedicated receptionist with a couple of main phone numbers (local and toll-free) that, utilizing Teams

Here are all of the steps we've tried:

  • Disabling the SIP ALG on the XG (on the recommendation that this can cause further problems; I'm tempted to re-enable it now that we've addressed some other issues)
  • DCSP and other QoS
  • Various firewall allow rules between subnets
  • Migrating users to Teams Only mode to address some of the issues with quality of service.
  • NAT rules, including both loopback and reflexive, between the WAN port traffic and the internal devices, primarily around the STUN ports (3478-3481), and the audio, video, and screen sharing ports (50000-500019, 50020-50039, etc.).

I realize there's not a lot to go on here (I'm sure after some comments I'll be providing screenshots), but after we've tried a little bit of everything, it's time to get some feedback from other community members on best practices.

Thanks.



This thread was automatically locked due to age.